Law / Portugal

Portugal

privacy

Portugal's private-sector regime is the General Data Protection Regulation (GDPR) plus Lei n.o 58/2019, de 8 de agosto (Lei de Execucao do RGPD), in effect from its 8 August 2019 publication. Portugal is the genuinely divergent jurisdiction in this wave: the CNPD, in Deliberacao n.o 2019/494 of 3 September 2019, announced it will decline to apply a set of Lei 58/2019's own provisions in its enforcement decisions on EU-law-primacy grounds, a supervisory stance rather than a repeal, and one that does not bind the courts.

Three independent secondary sources corroborate the disapplication mechanism and two specific provisions (the Article 28(3)(a) employee-consent restriction and part of the Article 37 to 39 penalties framework); they diverge on the rest of the list, so this document records only what is corroborated. As at 2026-08-24; no Portuguese court ruling on the deliberation's own validity has been located, and later amendment is not independently confirmed.

13 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Portugal

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Portugal, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Lei 58/2019 derogation from this timeline was identified in this pass.

What it asks of an app

Comprehensive regime

Lei n.o 58/2019, Portuguese GDPR Implementation Law (Lei de Execucao do RGPD)

cite Lei n.o 58/2019, de 8 de agosto stage In effect since 2019-08-08 source Diario da Republica Eletronico, dre.pt, official text listing

Portugal's private-sector regime is the General Data Protection Regulation (GDPR) plus Lei n.o 58/2019, de 8 de agosto (Lei de Execucao do RGPD, GDPR Implementation Law), in effect from its 8 August 2019 publication.

Portugal is genuinely divergent here: the CNPD, in Deliberacao n.o 2019/494 of 3 September 2019, announced it would decline to apply a set of Lei 58/2019's own provisions in its enforcement decisions, on the ground that those provisions restrict the GDPR's direct effect and full effectiveness contrary to the primacy of EU law.

This is not a repeal (the CNPD has no constitutional-court power to strike a provision down) and it does not bind the courts, which remain free to reach their own view if a disapplied provision is litigated; it is a supervisory authority's own prospective enforcement stance, published for transparency.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Portugal

cite Regulation (EU) 2016/679, Arts. 44-49 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Portugal outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Lei 58/2019 derogation broadening or narrowing this was identified in this pass.

What it asks of an app

Data subject rights

GDPR Article 22 and Lei 58/2019, Automated Decisions in Portugal

cite Regulation (EU) 2016/679, Art. 22; Lei n.o 58/2019, de 8 de agosto stage In effect since 2019-08-08 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Lei 58/2019 without narrowing per its own summary.

One of the CNPD's disapplied provisions, Lei 58/2019 Article 20(1) (restricting access rights where a confidentiality or secrecy duty applies against the data subject), sits in this dimension: only one of three secondary sources read this pass names Article 20(1) among the disapplied provisions, so this document does not treat that specific finding as settled, and the GDPR Article 12 to 23 baseline is recorded as controlling.

What it asks of an app

Enforcement supervision

CNPD Deliberacao 2019/494, Disapplication of Lei 58/2019 Provisions in Portugal

cite CNPD Deliberacao n.o 2019/494, de 3 de setembro de 2019; Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2019-09-03 source Three independent secondary paraphrases of CNPD Deliberacao 2019/494 (Lexology, Garrigues, Recording Law)

The CNPD is Portugal's supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. In Deliberacao n.o 2019/494 of 3 September 2019, the CNPD announced it will not apply a defined set of Lei 58/2019's own provisions in its enforcement practice, reasoning that an EU regulation has direct effect and primacy over conflicting national law under Article 288 TFEU and settled CJEU case law.

Three independent secondary paraphrases of the deliberation (Lexology, Garrigues, Recording Law) agree the CNPD disapplies Article 28(3)(a) (restricting employee consent to processing that would grant a legal or economic advantage) and a penalties-framework provision in the Article 37 to 39 range (differentiated fine ceilings by company size, and a prior-warning requirement for negligent infringements); the three sources diverge on the rest of the disapplied list (Articles 61(2), 62(2), and 20(1) are each named by only some of the three), so this document records only what all three corroborate and does not assert a complete article list.

Two direct attempts to read the deliberation's own primary text failed this pass (an HTTP 403 behind bot protection, and unparseable compressed PDF structure at two mirrors). GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it asks of an app

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Portugal

cite Regulation (EU) 2016/679, Art. 9 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Lei 58/2019 provision adding a distinct national biometric-specific derogation was identified in this pass; Lei 58/2019's own additions are concentrated in automated-decision rights and the CNPD's disapplication practice rather than a biometric-specific chapter.

No Portugal-specific voiceprint or faceprint case, deliberation, or regulatory guidance was located; this is recorded as an absence in this pass's search, not a confirmed absence in Portuguese law.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.